Tailored to help achieve the mission of simplifying complex compliance programs, we are capable of providing the following suite of services:
With a deep breadth of experience, we have assembled the most common suite of compliance solutions for your specific industry in mind:
Schellman performs thousands of projects each year for domestic and international clients.
In an industry of norms we have consistently applied our values to set ourselves apart which has allowed us to be a leader in the compliance world.
We provide IT audit and compliance attestations, and there are no upsells of other consulting services or financial audits.
All engagements at Schellman come with no hidden fees, unlike the Big 4 that offer traditional hourly billing.
All auditors are Schellman employees and no work is done “off-shore.”
Schellman principals, many of whom are former Big 4 auditors, play an active role on all engagements.
Schellman’s methodology is put to the test hundreds of times per year across different locations and business environments. With a scalable methodology, this approach largely remains the same which gives our clients the ability to include subsidiaries and related entities into a single audit effort.
Our process begins with the end in mind and always aims to lay the groundwork for future projects. With effective communication and timely coordination across these planning activities, Schellman has never missed a deadline and has consistently delivered on its goal of Quality, Above All.
After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the client are fully aware of the what, who, when, why, and how prior to the beginning of testing.
Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.
The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.
By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the client has the plan prior to the testing and on-site visit.
Testing and planning is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of planning the evidence needed for the objectives discussed.
Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and planning activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The client will have confidence the Schellman team has completed this phase timely and completely.
Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.
Schellman’s report takes into account the entire process and customizes a report for each client. The draft report will be provided within 3 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.
Working with some of the best organizations in the world, honest feedback is essential. We survey our clients after every engagement, and here is what some of them had to say:
PCI DSS Validation | Managed Service Provider
ISO 27001 Certification | Software Company
SOC 1 Assessment | Management Consulting Services Company
Demonstrating leadership through deliberate actions that support a more sustainable future for the marketplace, our people, the community, and the environment.
Schellman is the only Top 100 CPA firm to specialize in IT Audit and Cybersecurity. Not all CPA firms are created equally, and we pride ourselves on our differences. As a smaller firm, we are more visible; you are not one of the masses. Our team is made up of high performers who move quickly and thrive in an open environment.
At Schellman, we deeply understand the significance of our independent audit, assessment, and certification services within the expansive cybersecurity and compliance ecosystem. We take pride in our extensive experience collaborating with diverse providers, always maintaining a steadfast commitment to impartiality and avoiding any revenue sharing or conflicts of interest.
While Schellman does not engage in reselling or participate in referral fees, we firmly believe that fostering alliances throughout the market allows us to deliver exceptional solutions to our clients.